CVE Vulnerability Database

Search and browse 395,319 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-41699CRITICAL9.8Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a...
CVE-2026-41001MEDIUM5.3Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da...
CVE-2026-41000LOW3.7Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-ti...
CVE-2026-40999HIGH8.6When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ...
CVE-2026-40998HIGH8.2Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta...
CVE-2026-40997MEDIUM5.3Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis...
CVE-2026-40996MEDIUM4.8Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for ...
CVE-2026-40995MEDIUM5.4X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped...
CVE-2026-40994HIGH8.2Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di...
CVE-2026-40992MEDIUM5Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail...
CVE-2026-40987HIGH7.1A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the ...
CVE-2026-40986MEDIUM4.8Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not...
CVE-2026-10795HIGH8.1The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version...
CVE-2026-40985MEDIUM6.4Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions....
CVE-2026-35273CRITICAL9.8Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana...
CVE-2026-2827MEDIUM4.7The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati...
CVE-2026-53465MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25...
CVE-2026-53464MEDIUM4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25...
CVE-2026-53463MEDIUM4.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53462MEDIUM5.9ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53461HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53460HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-52726HIGH7.5Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to v...
CVE-2026-50223HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenti...
CVE-2026-49219MEDIUM5.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...